MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2a40a9e18303875b2db452783190820001c898e8374864fec29793bf43bbe401. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FormBook


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2a40a9e18303875b2db452783190820001c898e8374864fec29793bf43bbe401
SHA3-384 hash: 36df4643dc8180455808ce9b0165bb432d4b1ab023342dc010392b8f880dfa4a6409b57804065b72ae80566a8df2a7ac
SHA1 hash: 6a4b3520aeb0fce8a5bb1070df94cd508db3d120
MD5 hash: d5476744c2d527d8af35f32223cb653e
humanhash: low-mockingbird-helium-indigo
File name:blk(1).exe
Download: download sample
Signature FormBook
File size:808'960 bytes
First seen:2020-04-02 10:59:01 UTC
Last seen:2020-04-02 12:57:07 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 9838de482e5c72f1ec745619bda341ba (4 x AgentTesla, 1 x FormBook, 1 x HawkEye)
ssdeep 12288:LyjAJCW+3Iv+YKc7tt1scgW2tI3BVZVKnoOOJRRpdozJ0QzlAty7JTp:waaIvYitt1sB/eLKVOJR7SzJPhAo
Threatray 5'123 similar samples on MalwareBazaar
TLSH 7305BF36F1814C33C1B31A3DDD0B6368A82ABE512E2865466BF8DD4C9F39651FB291C7
Reporter oppimaniac
Tags:FormBook

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-02 11:35:36 UTC
File Type:
PE (Exe)
Extracted files:
2
AV detection:
29 of 31 (93.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FormBook

Executable exe 2a40a9e18303875b2db452783190820001c898e8374864fec29793bf43bbe401

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
COM_BASE_APICan Download & Execute componentsole32.dll::CoCreateInstance
ole32.dll::CreateStreamOnHGlobal
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteExA
shell32.dll::ShellExecuteA
shell32.dll::SHGetFileInfoA
WIN32_PROCESS_APICan Create Process and Threadskernel32.dll::VirtualAllocEx
kernel32.dll::CloseHandle
kernel32.dll::CreateThread
WIN_BASE_APIUses Win Base APIkernel32.dll::LoadLibraryExA
kernel32.dll::LoadLibraryA
kernel32.dll::GetSystemInfo
kernel32.dll::GetStartupInfoA
kernel32.dll::GetDiskFreeSpaceA
kernel32.dll::GetCommandLineA
WIN_BASE_IO_APICan Create Fileskernel32.dll::CreateFileA
kernel32.dll::FindFirstFileA
version.dll::GetFileVersionInfoSizeA
version.dll::GetFileVersionInfoA
WIN_BASE_USER_APIRetrieves Account Informationkernel32.dll::GetComputerNameA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegOpenKeyExA
advapi32.dll::RegQueryValueExA
WIN_USER_APIPerforms GUI Actionsuser32.dll::ActivateKeyboardLayout
user32.dll::CreateMenu
user32.dll::FindWindowA
user32.dll::PeekMessageA
user32.dll::CreateWindowExA

Comments